Salesforce can act as a single sign-on (SSO) identity provider to service providers, allowing end users to easily and securely access many web and mobile applications with one login. When using SAML for federated authentication, enable Salesforce as an identity provider and then set up connected apps.
From Setup, enter Identity Provider in the Quick Find box, select Identity Provider, and click Enable Identity Provider. By default, a Salesforce identity provider uses a self-signed certificate generated with the SHA-256 signature algorithm.